29 ms·
Are Xiaomi browsers spyware? Yes, they are (2020)
- phpisatrash 6y agoReally interesting. But whether what Xiaomi browser does it's a spyware, what's is Google? Does Google collects our navigation data? (Yes if we are using chrome or android and logged in) Does Google knows what videos and what kind of videos do we watch? (Do you need an answer?) Call it's a spyware because is a chinese company? Really? Nah. Google does the same or at least worst than it. I'm neither defending Xiami nor Google. The question is: almost every application does data collection. And if you call it as spyware, therefore every app which does data collection is a spyware.
- jzebedee 6y agoYes, they are both spyware. Call a spade a spade.
- EvilEy3 6y agoWhat does Google have to do with Xiaomi spyware? Or Google being spyware somehow makes Xiaomi spyware less shitty?
- techrat 6y ago>What does Google have to do with Xiaomi spyware? False equivalence. If people in here actually broke down the differences, they would have to admit that their "Grr, Google just as bad!" hyperbole is more than just a tad disingenuous.
- Decker87 6y agoI think it comes down to which companies and governments are on the other end. I'm far from trusting the US government, but I trust the Chinese government even less.
- guerrilla 6y agoI'm sure you have your reasons but for me I feel like I have nothing to worry about from China living permanently outside of their jurisdiction.
- _jal 6y agoThere is a natural tendency to compare and contrast. And especially in cases where people are speculating about political motives, you're going to see that. > Or Google being spyware somehow makes Xiaomi spyware less shitty? Absolutely not, but both of them doing it defangs certain types of criticism.
- dangwu 6y agoThey're definitely both spyware at this point. Shoutout to Firefox, which makes a conscious effort to block tracking cookies and not collect data.
- okl 6y agoBy the grace of their benefactor (Google)?
- Kelamir 6y agoCould you elaborate your point?
- okl 6y agoGoogle pays a lot of money to Mozilla to be the default search provider in Firefox. This creates a conflict of interest. https://www.zdnet.com/article/sources-mozilla-extends-its-google-search-deal/ https://www.zdnet.com/article/sources-mozilla-extends-its-go...
- neltnerb 6y agoApologies for not finding citations, but as an example of... suspicious behavior... Firefox had a big campaign about blocking Facebook tracking with a big push to install an addon to reduce Facebook data collection. They did not do that with Google. That's the one that stood out to me as especially asymmetric, others may have other examples they remember. Don't get me wrong, Firefox is clearly the best of the options available. I use it all the time. But I'm also very aware that there is a bigger bias against Facebook (don't actually care since I don't go near it and block its javascript and cookies) than against Google. Of course, it's not obvious that this is Firefox's fault, Google is extremely good at finding probably-shouldn't-be-legal workarounds to just about any attempt to retain privacy. You'd think making clear you want to retain your privacy should be enough, legally, but I guess there are no consequences.
- Daho0n 6y ago
- Darmody 6y agoGoogle doing something bad is not an excuse for others doing the same thing. Also Google isn't under the control of an authoritarian government who is committing genocide as we speak. I'm no Google fan and I dislike what big tech have become but I rather let Google have my data than the CCP.
- keepper 6y agoYes, it does matter that it's outside of US laws. Just like the inverse matters too. ( an American company collecting Chinese user data should matter to Chinese users ). This "whataboutism" is getting tiring. What Xiaomi does here is really bad. if google does/did the same thing it would ALSO be bad. There is no "but they do it too!". It's bad, period.
- nicolas_t 6y agoWell yes, I also call Chrome a spyware and don't use it. That's why I use firefox. And from what I read on HN, other people say the same thing about Chrome.
- Darmody 6y agoI'm using a firewall to block tens of IP addresses and several apps. Why would Xiaomi tell me to download a 26MB update from their store if the one from Google Play, where I downloaded the app it's less than 15MB? I'll be getting rid of this phone by the end of the month.
- La1n 6y agoMost Xiaomi phones are relatively easy to root/unlock and install a new rom on.
- okl 6y agoYep, here's the link to the LineageOS device list with installation instructions. https://wiki.lineageos.org/devices/#xiaomi https://wiki.lineageos.org/devices/#xiaomi
- antonzabirko 6y agoDid you really need to investigate this to realize it's spyware? This and chrome and most web browsers are spyware at this point.
- BelenusMordred 6y agoChromes "Software Reporter Tool" basically scans your whole computer and sends that data off to Google/NSA. It's literal spyware. Firefox doesn't do this.
- throwawei369 6y agoInstead Firefox uploads your geographical location to their servers every time it starts up. And before you ask, this telemetry cannot be stopped. And when you finally manage to do some therapeutic dissonance from the above default behaviour. Whenever you use the inbuilt DoH on Firefox, FF shares this stats with Cloudflare too.
- BelenusMordred 6y agoThankfully geographic location is simple on the internet
- walrus01 6y agoI truly don't understand, from a security and privacy perspective, why would anyone outside of China would voluntarily choose to run closed-source software from a company that's subject to domestic laws and regulations in China. The MSS is no joke. https://www.google.com/search?client=firefox-b-d&q=china+mss+data+sharing https://www.google.com/search?client=firefox-b-d&q=china+mss... This is the same reason that Zoom is banned at my workplace and many other partner companies. You've actually got two problems here. One is the commercial advertising/for-profit related data sharing problem described in the article. The second is that Xiaomi, as a company with that collected data resident in China on its servers, is obliged to provide a pipeline for a copy of their database to the MSS upon request.
- lucideer 6y agoCould it be the same reason anyone outside of the US would voluntarily choose to run close-source software from a company that's subject to domestic laws and regulations in the US? The ECPA is no joke.
- walrus01 6y agoI'm sure that a Chinese citizen would see the NSA as an equal or greater threat. The difference from my perspective is that as a citizen of a NATO country with a functioning democracy, I'm highly unlikely to be rounded up by my government and put in a prison or concentration camp for expressing my political opinions or religion. You only need to look at the past several years of news from Hong Kong and the Uyghur/Xinjiang province situation to see the stark real world difference in human rights, political freedoms and press freedoms.
- lucideer 6y agoI'm not 100% sure from your comment whether you're making out that: (a). China is bad (yes, known) (b). The US is not quite as bad (debatable but for the sake of argument lets agree that this is true) (c). The US is benign My comment was only refuting the 3rd supposition. I'm not sure if you actually believe this is true. Though terms such as "country with a functioning democracy" make me think you might...
- lucideer 6y agoInteresting to see the quite loaded (and slightly archaic in 2020?) term "spyware" used to refer to Chinese software. I haven't seen it used to describe Facebook or Google software, even alongside all of the recent news stories highlighting their apps' tracking footprint by Apple's newer iPhone AppStore requirements.
- aroman 6y agoI recently bought a Xiaomi phone (Poco m3) for development. I was shocked to learn that in order to enable USB debug mode in developer settings, I needed to BOTH: 1) make a Xiaomi account with and 2) insert a SIM card to the device (!) Is that not insane? Other people seem to think so too: https://android.stackexchange.com/a/186052 https://android.stackexchange.com/a/186052 Apparently the only alternative to this is rooting the device, which may break it.
- gruez 6y ago>2) insert a SIM card to the device (!) You need to insert a SIM AND use mobile data on it (ie. turn off wifi, enable mobile data). Just inserting a dummy SIM card won't work.
- nottorp 6y agoYes, I returned it and got a Samsung instead for this exact reason.
- aroman 6y agoAny model to recommend? Not sure if our usecases are the same -- I wanted to find a cheap "lower end of the market" phone to test my mobile game on. Frankly, the poco m3 might even be too powerful for that purpose...
- danlugo92 6y agoA10 or A01 are pretty slow
- eptcyka 6y agoNot a Samsung in my experience. They get slow quick and the bluetooth chip on mine died literally out of nowhere. After 3 months of use, no less. Get a pixel or a oneplus.
- nottorp 6y agoI have a Galaxy A21s now. It was just slightly more expensive than the Xiaomi i tried. Not sure how low end it is though. Mind, it's strictly a development phone. It sits on my desk plugged in, unless I debug those Android apps. No sim card in either. My personal phone is an iPhone XS.
- danpalmer 6y agoThis paragraph stood out to me: > The intention here seems to be that aigt is the timestamp when the ID was generated. So if that timestamp deviates from current time by more than 7776000000 milliseconds (90 days) a new ID is going to be generated. However, this implementation is buggy, it will update aigt on every call rather than only when a new ID is generated. So the only scenario where a new ID will be generated is: this method wasn’t called for 90 days, meaning that the browser wasn’t started for 90 days. And that’s rather unlikely, so one has to consider this ID permanent. If we assume that Xiaomi aren't literally trying to spy for a government and are in fact just poorly calibrated on what's legitimate to collect for product analytics purposes, this paragraph highlights why that's still incredibly dangerous despite "good intentions". I remember the UK government investigation into Huawei concluding that not only was their security posture insufficient for critical infrastructure, but their engineering practices were likely a decade away from being at a point where they could start to claim good security practice. This paragraph seems to suggest a similar problem at Xiaomi. This should have been caught at a security review stage during design, it should have been caught at the code review stage, it should have been caught by automated tests, it should have been caught by QA, it should have been caught once live by data tests, it should have been seen once live by analysts, it should have been fixed at so many different points. The fact it wasn't suggests that these stages either don't exist or are insufficient.
- michaelcampbell 6y ago> If we assume that Xiaomi aren't literally trying to spy for a government Is that even allowed by Chinese law?
- kzawisto 6y agoXiaomi is awesome phone for it's price tag you just needs to flash custom ROM like LineageOS. And they don't even make this problem contrary to other manufacturers like Samsung.
- ignoramous 6y ago> Xiaomi is awesome phone for it's price tag you just needs to flash custom ROM like LineageOS. There is likely tonnes of binaries that run outside of Android, so OEM you choose matters too.
- sandworm101 6y ago>>The article accuses Xiaomi of exfiltrating a history of all visited websites. Is this our definition of spyware? I see countless articles float by on HN about super cookies, spy pixels and browser fingerprinting. Those do effectively the same things, track users against their expressed wishes, but we just don't call them spyware.
- bronlund 6y agoThis is stupid. Google and Android is way worse than this.
- cwhiz 6y agoChinese browser collects your data? Spyware. American company collects your data? $1,400,000,000,000 valuation. This reminds me of how we call Russian billionaires "oligarchs" but we just call American billionaires...billionaires.
- mads 6y agoYes, I think everyone got the memo about American companies. Thanks though..
- yumraj 6y agoChinese browser collects data for CCP which will use it for spying and for action against you, your family and your country. American company will collect data to show you ads and profit. Are they really same?
- serf 6y agoAmerican agencies routinely collect data from the internet that results in actions against people. One could say the motives are different, but to act as if American groups collect data purely for profit isn't true. >Are they really the same? No, but acting similarly doesn't imply identical similarity.
- itsoktocry 6y ago>American company will collect data to show you ads and profit Unless you get a target on your back, in which case the American company will provide the American law enforcement agencies with whatever data they want to take action against you and your family. Your assertion is just a variation of "if you're not doing anything wrong you shouldn't worry about spying".
- godelski 6y agoFWIW I didn't read the gp as supporting data collection, only noting a difference between corporations gathering data and governments. I don't support data collection, but I do think the distinction is useful.
- justicezyx 6y agoHmm, I mean why Chinese capitalism is so powerful? Because the government sanctioned and allowed the capital's all-reaching power. Do you believe CCP is so capable to utilize such tools? If the answer is yes, then you should ask yourself is there any realistic chance of overpowering such a technologically advanced "government". And how much more powerful the private sectors would be. Think about how much gap is between silicon valley and US government in technological capabilities. This framing of pin everything as government sponsored activities make it very difficult to correct such behavior effectively. Because they were easily brushed off as intentional attack on the nation. Why not just put it as what is? I mean 996 in Chinese high tech industry is killing the quality of the work. That's obviously the right reasoning right?
- LegitShady 6y agoI don't think whatever point you're trying to make is very clear. There's a lot of insinuations and suggestions, but you're not actually making a point here.
- monkeyingaround 6y agoXiaomi phones are insane, at least BlackShark. They replace virtually all the major user level stuff of Android with extreme data collecting alternatives. They then make it so that you cannot disable many of them (via adp, custom ROMs etc.) without bricking the phone, I'm talking wallpaper or clock apps that run with full, non-modifiable privileges. They subsidize cheap hardware with truly insane level of tracking. They will also stop allowing custom ROMs once they've built up enough reputation, some newer models already will never have custom ROMs.
- trasz 6y agoSo how is it different from a regular Android again?
- monkeyingaround 6y agostock android apps have sensible default permissions and are modifiable, e.g. clock does not have unmodifiable access to every aspect of your phone. clearer?
- techrat 6y agoIf you cannot replace the software on the Black Shark with alternatives without possibly bricking the phone, I would say that's a substantial deviation from the norm where most other devices have unlockable bootloaders and Rom support using LineageOS.
- a_imho 6y agoA run of the mill iphone is much worse in that regard.
- tkinom 6y agoI have a 5 years old oppo phone and decide to use it as podcast device. A few odd thing about this phone: 1) My Google, IG accounts both sent me security alert about successful login attempt from from Thailand, Vietnam. I 100% sure I only created the IG from this phone once and have not used that password from anywhere else. IG Username / password was taken from this phone and attempt to be login from somewhere else. 2) I can't get the phone to disconnect from wifi. I put the phone on airplane mode, disable wifi, bt, etc. Manually change the wifi password to something else. it always successfully reconnected back after a few days with old password. There are logic in the phone can try very hard to state connected online. It remembers old password and successfully connect successfully with it after a few days. Only rename the wifi ap in my router seems to finally permanently disconnect it from the network. 3) I have let the phone back online and created Google account that is 100% unique to this phone. Love know how long would it take for the login attempt for that G account from Thailand/Vietnam start to show up.
- anovikov 6y agoThe whole notion of "spyware" in today's world is relative. Everything is a spyware these days.
- o_p 6y agoXiaomis are pretty good and cheap, funny that one would care about the browser (which is optional, as you can install any browser you want) while Google owns your entire OS, but China bad US good amrite?
- monkeyingaround 6y agoi can't remember the last time i felt fear expressing my beliefs on my phone here in the USA so you tell me
- o_p 6y agoSure unless you are someone whos beliefs actually matters like a reporter and the CIA hacks your car driving assistance or you are found dead by suicide of two shots in the head.
- monkeyingaround 6y ago...and the goalposts shift
- guerrilla 6y agoI guess that means you're pretty mainstream then. Sucks for Muslims, anarchists, journalists, activists, etc.
- monkeyingaround 6y agoas a muslim i can confirm you have nothing of content behind your ideology
- dheera 6y agoIn other news, Xiaomi Roborock vacuum cleaners require you to enable GPS permissions and transmit back Wi-Fi PASSWORDS and floor maps back to their server. They've really been on a privacy invasion spree lately.
- LegitShady 6y ago...I returned a scale to amazon that required an app on my phone and location be on when its registered. For a scale. Wouldn't work without it.
- dheera 6y agoDid it require SMS confirmation too? lol In any case I hope you gave it a 1-star review.
- LegitShady 6y agoI did but looking for truth in amazon reviews is a work in futility anywas
- powerapple 6y agoUnfortunately, xiaomi's business model is to sell hardwares with little to none profit margin and make profit as a internet company, I.e. advertising and so on. I give them the benefit of doubt that 90 days renewal was added and didn't work due to not unit tested maybe. Still, it is the same ad business as fb. I love the look of their phones, but I would pay for an iPhone for the benefit of secure os and better privacy
- dicomdan 6y agoThey give away low cost hardware because it's a military branch of the government whose purpose is establishing a global surveillance network. Being profitable is a nice to have but not a primary purpose as they get subsidized by the state regardless.
- powerapple 6y agoOkay. So Chinese government keeps pumping money into Huawei, Xiaomi, Tencent, Alibaba, Tiktok and many other businesses so that they can ..... make money? You have to ask an economist for how this works, I am not intelligent enough to figure it out.
- api 6y agoI assume that anything is spyware unless proven innocent, especially on mobile where surveillanceware is effectively the whole purpose for the platform's existence.
- samstave 6y agoARE YOU FN KIDDING ME: Anything from CCP is pyware - especially when the FN namesake is XI Jinpooh.
- aboringusername 6y agoAre [computers] spyware? Yes, they are (2000) should be the title. If you use a computer, smartphone or IoT device then yes, it collects data, just as Facebook runs ads. What's collected these days: Your social circle, every time you connect to the mobile network, when, which tower you connected to, tx/rx bytes, who you phoned, where the callee is located Whether you're in a car, walking (sensors) Whether your sleeping...(a recent Google blog post talked about a new "sleep tracking" API). You generate data as a human, interested parties (governments) collect that and will store it for the rest of time. I suspect there's a database of every URL visited by any human in the last 20 years. This is not surprising and should surprise nobody.
- deleted 6y ago[deleted]
- t0astbread 6y agoDo you mind providing citations?
- phh 6y agoThat's amongst the reason I do my AOSP GSI ( https://github.com/phhusson/treble_experimentations/releases/ https://github.com/phhusson/treble_experimentations/releases... ; Generic System Image, an Android that works on pretty much all recent Android phones). Xiaomi devices are usually at sweet spots price/performance-wise (not really great hardware imo, but well). With custom ROMs (including my GSIs, but other custom ROMs are fine as well), buy a phone for their hardware, not for their software. (BTW my daily driver is a Pixel 5... not running Google adwares! Only high-end-ish device that fits my hand). However, Xiaomi devices are bricks for like a month, because before being able to install your own software, you need to be approved (connecting a smartphone on a Windows computer), and it's only once you get your smartphone that you can install your own software.
- lostmsu 6y agoMy problem with GSI was last I checked (1 year ago) it still did not support storage encryption (Max 3), and SELinux was off. Awesome project though.
- phh 6y agoUh, both have been forever wrong using my GSIs? I've never made any GSI without storage encryption, and My GSI have always been running SELinux enforcing. Some kinds of GSIs have those kind of issues, but it's only those that are binary ports from OEM ROMs, like port from Xiaomi or OnePlus ROMs, but proper source-based GSIs shouldn't have those issues.
- lostmsu 6y agoHm, I distinctly remember using specifically your GSIs mid 2019 (and would love to return to them) on Mi Max 3. In early 2020 XDA thread [1] I was suggested to use phh-securise to reenable SELinux, which suggests that it was not enabled by default at least back then. Never got to try phh-securise, since the encryption part of the response was not definitive. [1] https://forum.xda-developers.com/t/guide-nitrogen-10-10-phh-quack-los-17-gsi-with-android-10-vendor.4029411/page-3 https://forum.xda-developers.com/t/guide-nitrogen-10-10-phh-...
- ed25519FUUU 6y agoOur schools are dumbing down math and removing advanced classes (if you can even go to school) because of “white supremacy”, meanwhile China is investing full speed into engineering disciplines and is performing extremely effective espionage against virtually all Americans. I don’t know if there will ever be a sino-American war, but if there ever is one it’s going to be very painful for us.
- asien 6y ago> If you use Mint Browser (and presumably Mi Browser Pro similarly), Xiaomi doesn’t merely know which websites you visit but also what you search for, which videos you watch, what you download and what sites you added to the Quick Dial page Yet people in Europe they LOVE Xiaomi. I swear I’ve seen so many of my friends with those high end 500$ phones. Even if they are tech guys it’s like they just don’t care , they want the most powerful phone with the most features at the cheapest price. At this game Xiaomi and other Chinese brands have become very good. That being said Google as been doing the exact same thing for 30 years. Nobody ever considered banning google from anything.
- Daho0n 6y agoI live in Europe. If I weren't a privacy nut I'd pick Xiaomi any day over Apple or Google. Now I use Android with OPNsense in front of it via VPN. Chinese phones doesn't log more than the other smartphones.
- cwkoss 6y agoHow does this compare to google chrome's data collection?
- systemvoltage 6y agoI am truly appalled at the level of discussion from intellectuals as I consider on HN. Comments here are repeatedly evaluating whether the same thing would apply to US. I expect more from HN. Can we please discuss the problem in isolation and especially the interesting technical bits? Ask yourself, this kind of exploitation is bad regardless of whether any country does something similar. It's anti-user in every possible interpretation.
- La1n 6y ago> Can we please discuss the problem in isolation and especially the interesting technical bits? Sure, but you also see this problem doesn't exists in a vacuum. Noted by you bringing up concentration camp numbers in this exact comment section. Maybe you should listen to your own advice?
- systemvoltage 6y agoI think this is a general trend in China based discussions. Problem does exist in a vaccuum. Xiaomi phones have nothing to do with Google or any US based tech. I am highlighting the absurdity of evaluating US ad-tech to 2 million people in concentration camps.
- Karunamon 6y agoThe only difference there is what the exfiltrated data is being used for. The real problem is one level higher, that the data is being exfiltrated in the first place.
- hungryhobo 6y agoi think it provides context, if what they are doing is status quo, then maybe we should question the status quo rather than an individual company.
- firebaze 6y agoChrome is the definition of spyware, just by widely know facts. Doesn't make Xiaomi browsers better, I know. Still 90%+ use Chrome. I know noone using a Xiaomi browser.
- novaRom 6y ago> Xiaomi now announced that they will turn off collection of visited websites in incognito mode. That’s a step in the right direction, albeit a tiny one. They may also collect fingerprints and other biometrics (voice, pictures) in a similar misleading way. There's a lot of wise tricks others have learned from Google. IMO only strict laws forbidding data collection from smartphones completely will change that.
- firebaze 6y agoI use a Huawei matebook D14 as my personal device. Its primary use is in a WiFi-network (as in 99% of the time). Since I also use MS devices in the same network I log all IPs being accessed from my network (https://www.raspberrypi.org/documentation/configuration/wireless/access-point-routed.md https://www.raspberrypi.org/documentation/configuration/wire...) I'll leave the log results of accessed IPs as an exercise to the reader. Hint: no chinese/russian IP addresses are being accessed. I'd guess a lot more people use Huawei devices (before they were outlawed) than explicitly using a Xiaomi browser. And a lot of people didn't forget Snowden. Addendum: I use a MacBook pro (32gig, I7) and a Win10 pro work device (32gig, I7) as well. Neither contacts China or russia. Both of them submit ~10x of unknown traffic than the Huawei device. I don't want to paint the chinese dictatorship as "good", not at all. But I do want to remind that the US is - as experienced by an EU consumer - worse. Not now, but maybe in the future, at least according to collected data.
- ckozlowski 6y agoI suspect that your point is that "a Chinese device doesn't mean it's reporting to China." I think it's good not to make this assumption. That said, I also think it's incredibly naive to think that a collection system wouldn't make use of a local proxy to mask the ultimate destination of the information. It's such a trivial task to do, and provides a host of benefits to obfuscate and sow doubt as to where the data is going and will be ultimately used for. I'm not assuming that "it must be reporting back to China through a proxy!", but rather, the absence of certain national IPs in that list shouldn't be used to rule out scenarios either. An idea scenario for me would be that the device didn't call back period, or if it did, it did so to endpoints that could be authenticated and audited.
- firebaze 6y agoIt's incredibly naive to assume NSA/* doesn't do the same, even if that affects your daily life as a human/business owner about as much. I despise the chinese government - may it concern Uighurs or the treatment of Tibetans. Still I have a hard time believing none of my data collected by google is used by the US administration, which, as we know, is not always lead by a trustful person. Still, if I had to choose whom to embargo, I'd definitely choose china/russia. Since it's so easy to cheat traffic, there are two options: only china/russia needs to cover traffic, or ...?
- crazypython 6y agoA very good rule of thumb: Freedom-respecting (fully, 100% open-source) software won't screw you. Simply knowing someone could be watching you and your source code reduces the chance of malicious code.
- userbinator 6y agoThe Linux kernel is 100% open-source. Yet it's growing user-hostile features --- https://news.ycombinator.com/item?id=26285683 https://news.ycombinator.com/item?id=26285683 --- and guess what all the locked-down Android phones run...? Open-source doesn't mean anything for freedom if all you can do is look, because you don't have the signing keys and such to modify what you want. It just means they get to show you exactly how they put the noose on you, that's all. Firefox is also chock-full of "telemetry" and it's 100% open-source. That one you do get to modify, but it's still a bloody bastard to strip it all out and recompile to your liking.
- crazypython 6y ago> The Linux kernel is 100% open-source. Yet it's growing user-hostile features --- https://news.ycombinator.com/item?id=26285683 https://news.ycombinator.com/item?id=26285683 --- and guess what all the locked-down Android phones run...? That feature is optional, and depends on proprietary, closed-source TPM firmware. You just proved my point– it has to be 100% open-source to respect your freedom. > Open-source doesn't mean anything for freedom if all you can do is look, because you don't have the signing keys and such to modify what you want. It just means they get to show you exactly how they put the noose on you, that's all. I agree. That's why I prefer the term freedom-respecting software. Under the free software definition, that is no longer FLOSS, because users do not have the right to modify the software. > and guess what all the locked-down Android phones run...? Alas, Linux is not under GPLv3, which ensures that users have an equal right to modify their software. > Firefox is also chock-full of "telemetry" and it's 100% open-source. That one you do get to modify, but it's still a bloody bastard to strip it all out and recompile to your liking. Get a prebuilt build of LibreWolf: https://librewolf-community.gitlab.io/ https://librewolf-community.gitlab.io/ That it's fully open-source checks Mozilla's power to do abusive things. Telemetry can be disabled in Firefox settings. I've used both of your examples to advance my point further. 100.0% open-source = freedom-respecting and non-abusive.
- wooptoo 6y agoWhat's worse is that the whole OS is actually spying on you, not just the Mi browser. Even when idle my phone is trying to send bits of data to their servers. Xiaomi are great but for me this is the end of the line with their phones. Privacy comes at a premium nowadays and lots of us are willing to pay for it. Those affected can block the following domains from resolving: - data.mistat.intl.xiaomi.com - sdkconfig.ad.intl.xiaomi.com
- Daho0n 6y agoUsing pihole is effective but don't try blocking a Chromecast like this. I did and even using two piholes the network got killed by these hundreds of DNS requests per second to Google.
- aembleton 6y agoAlso tracking.intl.miui.com
- throwawei369 6y ago> data.mistat.intl.xiaomi.com Ah. I'd recognize this spy domain anywhere since it regularly features in my pihole's top 5 blacklisted ones
- f430 6y agoThis surprises no one.
- unnouinceput 6y agoQuote: "However, you have to make sure that you have “Incognito Mode” turned on and “Enhanced Incognito Mode” turned off – that’s the only configuration where you can have your privacy." Does the article's author really believe this or is put there because of outside pressure? I, for one, would not believe that for a single second.
- nuker 6y agoReplace Xiaomi with Google and article will still be valid.
- stephc_int13 6y agoFor anyone trying to be privacy conscious, by deleting their FB accounts, not using all the Google services etc. It should be obvious that a good rule of thumb would also be to not use software built in China. Even if they were not built with malicious purpose, they have both excellent state-funded hackers and poor security practices in most of their consumer products. Unfortunately, from what I've seen, I think the same can be said about software from Korea/Japan...
- Black101 6y agoI think that its the first time I see a headline with a question mark and the answer next to it...
- lovelyviking 6y agoWhy don't we address the root of the problem? Who controls computer? If user of computer (with phone features) doesn't have a full control over it then this situation can and will be abused by some one who does. It seems a logical consequence of not having full control over your own computer. Why we discuss mostly the degree of such abuse and not the core of the problem ? Another core of the problem is dealing with communist regimes. We never learn? Communists are literally responsible for millions of deaths in the 20th century.(https://www.youtube.com/watch?v=NDTbNmUgeXk https://www.youtube.com/watch?v=NDTbNmUgeXk) They have a good record of disrespecting human rights. Why someone sane would expect them to respect any of his rights now?
- tomc1985 6y agoBecause there is a lot more money to be made when you don't control the computer. We are in the middle of a data gold rush. Business types can't resist.
- lovelyviking 6y agoReminds me a bit logic of a thief which just can't resist.
- SilverRed 6y agoBecause it hardly makes a difference to power users, let alone average people. The Pixel phones come loaded with Google spyware, but you can flash your own rom on it to do whatever you want. But unless someone is out there developing an alternative rom without spyware that does everything you need, it may as well be locked down.
- superkuh 6y agoI couldn't agree more. Software companies have latched on to the idea that they can sell software but the users can never own the software. This naturally led to worse abuses when the software could be loaded over a network. But the core problem is the assertion of ownership and control.
- pid_0 6y agoAre all chinese products spyware? Yes, they are. Don't use chinese brands for phones, software, etc.
- Roritharr 6y agoI wonder more about their routers. For their specs they are extremely price competitive. Their AX6000 features a 2,5GBE Port, 4*4 5GHZ Antennas with supposedly 4800mbit/s max throughput over all clients for 120€ with shipping to the EU. The Netgear Orbi Pro is the only AP I could find that is similarly equipped and costs a handsome 400€. The mostly chinese and russian reviews on YouTube seem to show those numbers to be at least not ouright lies, but people on the OpenWRT Forums talk about the Routers talking quite a lot back to China. I really wish for somebody credible to do a teardown to look into these boxes.
- nirui 6y agoWell, if you're patient enough to sit through all the Chinese text, here is the teardown (with picture) you've been looking for: https://www.acwifi.net/12621.html https://www.acwifi.net/12621.html. Also that router is currently on sell on JD.COM (https://item.jd.com/100017450204.html https://item.jd.com/100017450204.html) priced at ¥599.00, about 80€ I guess. There are rumors says Xiao Mi has somewhat subsidized their line ups with intention to create their own ecosystem. If true, that's one of the reason why their devices can have such low price. On the other hand, ¥599 is not exactly cheap in China. Somebody can literally survive a entire month on that amount of money. A "normal" price for a "regular" router is around ¥70~¥200.
- nicolas_t 6y agoOn the other hand, ¥599 is not exactly cheap in China. Somebody can literally survive a entire month on that amount of money. -> Not in any major tier 1 or tier 2 cities. Used to be possible a long time ago but nowadays, that'd be really tough
- goodells 6y agoRelated to Xiaomi, the company is also doing some sketchy things in the smart home space under their brand "Aqara". I use HomeKit in my apartment and opted for Aqara branded wireless buttons and temp/humidity sensors because of the attractive hardware and good reviews. The devices require a wi-fi connected hub, not too strange for things that use Zigbee, so I gave that a go. Well, on cursory examination, the Aqara/Xiaomi hub was talking to a bunch of Chinese servers constantly. I didn't dive too deep into what all they were actually for. When I blocked the device from phoning home with my router, all the connected devices stopped working! None of the buttons or sensors would work, the RGB light on the hub couldn't even be changed. As soon as it lost the ability to ping its servers in China, the thing actually started strobe light flashing blue. Re-enable the outside network access on it, starts working again. This was totally antithetical to why I use HomeKit in the first place, so I removed the hub and paired all the Aqara accessories with a generic open source Zigbee hub (ConBee II) and added it to HomeKit with HomeBridge. In the future I plan to give brands more scrutiny before investing time/money in them and granting them unfettered access to my LAN...
- bombcar 6y agoIt’s absolutely infuriating how many IoT devices round trip to the cloud for no good reason at all.
- baybal2 6y agoThe thing is, they really don't. They just stop working after few minutes of no connectivity. No real roundtrip happening.
- helloworld11 6y agoNot quite for no good reason at all. For someone else who programmed them to do this, it is for a very self-servingly good reason of data vacuuming obsession, it just happens to be no good reason for the customer.
- nialv7 6y ago> The devices require a wi-fi connected hub, not too strange for things that use Zigbee Wait, why would Zigbee devices require Wi-Fi connection? That would be a red flag for me, I would have avoided products like this.
- dirtyid 6y agoXiaomi makes money off services. Tracking subsidizes hardware. It's a business model. There's always option to unlock.
- de6u99er 6y agoThat's why I will never vecomr a billionaire. I would never do something to someone else, that I don't eant to be done to me.
- throwawei369 6y agoI can tell your age by this comment. I'll leave you with this quote. "You either die a hero, or you live long enough to see yourself become the villain"
- justplay 6y agoIt is not just Xiaomi; oppo/vivvo/realm too, track every things.
- victorfonseca 6y agoSorry, but... it's not the same thing Google and Facebook are doing from the last forever?
- usr1106 6y agoI know close to nothing about Android development in general and absolute nothing about Xiaomi in particular. When looking at the code snippets in the article I wonder about the variable names. This doesn't look like decompiled code. And I don't think their whole browser is open source. What am I missing here?
- kartoshechka 6y agoTo make discoveries like that harder and protect software from commercial standpoint, its code obfuscated before shipping. Something similar modern JS frameworks do to make code smaller and ship it through network faster
- usr1106 6y agoSure, that's what one would expect. But the code snippets in the article where surprisingly readable. That's what I didn't understand.
- 0xbadcafebee 6y agoMy old Huawei phone is still my favorite phone ever. I don't care if they spy on me. Take my data, I don't care! I just want another phone that good and that cheap.
- ComodoHacker 6y agoI believe Xiaomi being Chinese is kind of red herring here. The thing about big data is you never know in advance what kind of data can turn into a gold mine for your business. So the strategy "collect as much as you can afford and get away with" is economically reasonable if not optimal. Until this changes, nothing will change. And Xiaomi is not an exception here.
- charcircuit 6y agoSpyware is based off intent. Collecting data doesn't necessarily make you spyware. You can literally call anything spyware depending on how schizo you want to be at this point.
- unionpivo 6y agoThis is bad argument nowadays. Even if they just collect the data now, they might sell it 5 years down the line. You have to consider the worst possible interpretation, even if its not true today. Companies can be sold or taken over, go bust and their assets get sold. Companies can change too. Look at google. In 2000's I trusted google a lot more than I trust it now. You can bet google still has all my data from 2000's.
- rbrbr 6y agoAnd so is Google Chrome. Basically everything Android. Just don’t use that platform if you care about your privacy. And stop pretending just because millions use it or because it is supposedly more customizable. Google is Google.
- panpanna 6y agoXiaomi devices are officially sold in EU. Wouldn't a GDPR violation basically kill the company?? Note that Xiaomi is a Chinese startup hub, started by former googlers. 90% of what they sell is produced by Chinese startups. (That being said, I would use never Xiaomi software myself. I only use their hardware with open source 3rd party apps)
- cavendish3313 6y agoAs an app developer, I found no serious APP did not collect user actions for optimizing.
- Alex701 6y agoThanks for information.. https://bit.ly/2NKpX9X https://bit.ly/2NKpX9X
- bobthechef 6y agoNot surprising. I don't see how you can expect any less of this, even in the US. American companies collect vast amount of information that are either acquired by the state later on, acquired via some deal with the state, or some network of revolving doors is further entrenching US-style state capitalism which erases the distinction. Frankly, American corporations are effectively more powerful than the government at this point, at least in certain domains (like where freedom of speech is concerned). It'll only get worse until something gives. And given that American greed funded the wealth and power of the CCP in the first place, given the massive investments in China, I do not expect the globalist American imperial oligarchy to change course. Why would they? They like what the CCP is doing. They share more in common with the Chinese ruling class than with most Americans.
- jmacjmac 6y agoXiami is widespread brand in many countries because its products are really cheap and looks like this trend will continue for the next years. It's very frustrating to see this. Western world should impose standards to prevent it.
- happppy 6y agoblock every company that tries to compete with US companies. First it was Huawei, now its Xiaomi. Fb, Google are both US companies nd they literally track the hell out of their users to target ads but they are doing great, never had much issue except Zuckerberg was in the news a few months ago but US didn't block them, because they are US companies nd bring $$$ into the country
- utbabya 6y agoQuick scrolling through the comments, I wonder how many people actually RTFA? Looking at the list of things they collect, how could it possibly be legitimate, or compared to what "western" or any other companies are doing? - Full URL history - Full search history: engine and terms etc - Full download history - Full youtube activities: search, which video, for how long This is full blown home phoning trojan horse.
- zouhair 6y agoOh, well. I was just about to buy a Poco m3 2 days ago. I guess I wont. A Moto G Power I guess.